Skip to content

Repository files navigation

github-actions

Reusable GitHub Actions workflows for the datasciencecampus GitHub organization.

This repository contains workflows that depend on datasciencecampus organization-scoped credentials and policies. For broadly reusable workflows that do not require this organization-specific boundary, use ONSdigital/ons-github-actions.

Overview

This repository currently provides four public reusable workflows:

  • add-issue-to-projects: add new issues to one or more datasciencecampus ProjectsV2 boards.
  • add-pr-to-projects: add new pull requests to one or more datasciencecampus ProjectsV2 boards and set configured field values.
  • security-analysis: scan GitHub Actions workflows and infrastructure-as-code for security issues using zizmor and checkov.
  • terraform-quality: check Terraform formatting, validate configuration, and run TFLint.

The project workflows each have a matching internal implementation workflow. Their public workflows are the caller-facing contracts; the internal workflows own the privileged workflow_dispatch path and project mutation logic.

Workflow Catalog

security-analysis

Orchestrates GitHub Actions security analysis with zizmor and infrastructure security scanning with checkov. Runs automatically on push to main and pull requests against main, and can be called from other repositories.

terraform-quality

Checks Terraform configuration with terraform fmt, terraform validate, and TFLint. Callers can select validation directories and Terraform version, and enable or disable each check.

add-issue-to-projects

Adds opened issues to one or more datasciencecampus Projects by project number, with optional field updates.

add-pr-to-projects

Adds opened pull requests to datasciencecampus Projects and sets configured field values, for example Status = Review.

Consumption Model

Consumers should call the public reusable workflows from other repositories using uses:.

  • The add-issue-to-projects and add-pr-to-projects workflows dispatch the release tag recorded in metadata alongside the invoked workflow revision by default.
  • Set implementation_ref on either project workflow only when you need to override that release-managed dispatch target with a specific branch or tag.

Important

Public repositories that trigger these workflows automatically from issue or pull request creation events must restrict those events to trusted actors, for example by allowing only collaborators to open issues or pull requests. Configure this in the caller repository at https://github.com/<owner>/<repo>/settings under Settings > General > Features, then use Issues > Issue permissions or Pull requests > Pull request permissions as appropriate.

The full caller-facing contract, including required inputs and implementation_ref behavior, is documented in docs/reference/reusable-workflows.md.

For a visual explanation of the caller flow, internal dispatch hop, and trust boundaries, see docs/explanation/workflow-trust-boundaries.md.

Documentation

About

Reusable workflows for the Data Science Campus GitHub organisation.

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages